Quick Overview
Job Description
Job#: 3054548
Job Description:
Job Description: Job Description: Tier 1 Cyber Security Analyst (SOC)
Position Summary
The Tier 1 Cyber Security Analyst is responsible for the initial monitoring, detection, triage, and escalation of security events within a 24/7 Security Operations Center (SOC). This role serves as the frontline of cyber defense, leveraging SIEM and SOAR platforms to identify potential threats, investigate alerts, and ensure timely escalation according to established incident response procedures. This position requires a highly motivated, curious, and analytically driven individual who can think critically, adapt quickly, and operate effectively in a fast-paced environment.
Key Responsibilities
Monitoring & Alert Triage:
- Monitor security events and alerts from SIEM platforms (e.g., Splunk) and other security tools.
- Perform initial triage and investigation of alerts to determine severity, scope, and potential impact.
- Analyze logs, network activity, endpoint data, and email security alerts (e.g., Proofpoint).
- Enrich alerts with contextual data (threat intelligence, asset data, user behavior).
Incident Handling & Escalation
- Follow defined escalation paths to Tier 2/3 analysts based on severity, confidence, and impact.
- Document incidents, findings, and actions taken in case management systems.
- Execute basic response actions using SOAR platforms (e.g., Splunk SOAR).
- Assist in containment actions under guidance.
SOC Operations
- Support 24/7 SOC operations, including shift work.
- Participate in shift handoffs.
- Maintain situational awareness of threats.
Platform & Tool Usage
- Utilize Splunk SIEM.
- Use Splunk SOAR for automation.
- Investigate email threats using Proofpoint.
- Work with Microsoft and Azure security tools.
Continuous Improvement
- Improve alert fidelity and reduce false positives.
- Provide feedback for detection tuning.
- Stay current on emerging threats.
Required Qualifications
Education & Experience:
- Minium 2 years of experience in 24/7 SOC environment preferred
- Associate degree in Cybersecurity, IT, or related field OR equivalent SOC experience.
- CompTIA Security+ Certification Required
- Experience with Splunk, Splunk SOAR, Proofpoint
- Experience triaging alerts and escalation processes
- Knowledge of networking fundamentals and log analysis
- Familiarity with Microsoft and Azure platforms
- CompTIA CySA+ (preferred)
- Splunk Core Certified User
- Microsoft Security certifications (e.g., SC-200, AZ-500)
- Analytical thinking
- Attention to detail
- Strong communication
- Adaptability
- Curiosity and initiative
- Team collaboration
- 24/7 SOC environment including nights, weekends, and holidays
- On-call or extended hours during incidents
- Mean Time to Triage (MTTT)
- Escalation accuracy
- False positive reduction
- Documentation quality
- SLA adherence
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.
Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.
If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, please contact our Benefits Department at or . Please note that this contact information is strictly to be used for medical ADA accommodations and that no other inquiries will be answered.
UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.
Similar jobs
- AK
Cyber Security Analyst III - Remote
NewAkima, LLC
DC🇺🇸$130k - $150k/yrRemoteYesterdayTechnology - TE
Senior Network Security Engineer
NewTECKpert
Tallahassee, FL🇺🇸$85/hrRemoteYesterdayAWSAgileAzureTechnology - GT
Security Engineer (Threat Modeling)
NewGoldenpick Technologies LLC
Seattle, WA🇺🇸On-siteYesterdayMicroservicesBashLLM+1Technology - SN
Need Network Security Engineer F5 & Palo Alto for Fulltime
NewSnapCode Inc
Atlanta, GA🇺🇸HybridYesterdayAWSLoad BalancingTCP/IP+2Technology - HT
Security Engineer – Cribl / SIEM
NewHansen Talent Group
United States🇺🇸HybridYesterdayBashPythonTechnology - LE
Cyber Defense Analyst
Leidos
Suitland, MD🇺🇸$87.1k - $157.4k/yrHybrid2 weeks agoRubySplunkC+++6Technology